{
 "schema": "bumplog.app.v1",
 "generatedAt": "2026-07-26T13:02:49.520Z",
 "slug": "frigate",
 "name": "Frigate",
 "repo": "blakeblackshear/frigate",
 "latestVersion": "v0.17.2",
 "safeToUpdate": "caution",
 "rationale": "The release contains no breaking config changes or required migrations, making the update itself straightforward. However, the security advisories — particularly the three unresolved issues around viewer-role privilege escalation and camera ACL bypasses — mean operators with publicly exposed instances or mixed-role user setups should review the advisories carefully before and after updating to understand residual risk.",
 "changelogSummary": "v0.17.2 is a maintenance release that patches six security vulnerabilities, several of them critical — including two remote code execution issues via go2rtc stream handling, RTSP credential leaks through nginx proxy caching, and authorization bypasses affecting viewer-role users. Three additional security issues affecting viewer-role privilege escalation and camera ACL enforcement are acknowledged but deferred to future releases. On the feature side, MP4 exports can now optionally embed recording segment chapter metadata, live page preview performance has been improved, and non-admin users can now use PTZ controls for cameras they have access to.",
 "sourceUrl": "https://github.com/blakeblackshear/frigate/releases/tag/v0.17.2",
 "lastChecked": "2026-07-02",
 "successor": null,
 "url": "https://bumplog.org/apps/frigate/",
 "badge": "https://bumplog.org/badge/frigate.svg",
 "lifecycle": null
}